Junglewise Threat Intelligence

CVE-2026-83030: Oracle Managed File Transfer authorization bypass in MFT Runtime Server

CVE-2026-83030 · Severity: high · CVSS 8.3 · Published 2026-09-15

Vendors: Oracle.

Executive brief

Oracle Managed File Transfer is a file exchange and integration component within Oracle Fusion Middleware used to securely transfer files across organizations. A vulnerability in the MFT Runtime Server allows authenticated network attackers to read, create, delete, or modify critical data, and can cause service outages. This could result in unauthorized data access, data loss, or interruption of critical file transfer operations.

Technical details

The vulnerability is an authorization bypass in the Oracle Managed File Transfer MFT Runtime Server component, exploitable via the T3 and IIOP network protocols. The flaw requires low-privilege authentication and network reachability to the affected server, but does not require user interaction. Successful exploitation permits an attacker to read, create, delete, or modify critical and accessible data, and to cause denial of service through hangs or crashes. Patches are expected from Oracle's standard Critical Patch Update process for the affected versions 12.2.1.4.0 and 14.1.2.0.0.

Affected products

  • Oracle Managed File Transfer 12.2.1.4.0, 14.1.2.0.0

Timeline

  • 2026-09-15: disclosed

References